Sign inSign up
MongoDB

dhi.io/mongodb

MongoDB 8.0.x (compat)

CIS
linux/amd64
debian 13
Tags:

8.0-compat, 8.0-debian-compat, 8.0-debian13-compat, 8.0.32-compat, 8.0.32-debian-compat, 8.0.32-debian13-compat

Index digest:

sha256:0edc791131e2c69e93ab222127e279a9a51340dc6cd7f7fcaf2597707d463bd7

Manifest digest:

sha256:3c84e490db0060f208cd787a80ae70bbb7cc8af2d9a20089428ddd9ec5921d77

Size

180.75 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mongodb:8.0-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mongodb:8.0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mongodb@sha256:a7de26cc7d97b23017751b062b165952f5802bdc3b38b3809eaedd4f07f42c27
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mongodb@sha256:86c5c95f42edb87e83183d8abedab99cc9ec5e78309a24c98288ecdd5a78bc37
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mongodb@sha256:be566f5ff3cb6b96766be4e5d423308239c24e66359907a0019f90a30961d3a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mongodb@sha256:3d4bad11b1ec076fd93a96eeb3a3619ba9416092eee7c1f0d46853e139538820
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mongodb@sha256:005c0125b03e3c08460284de69dee3ed7536a2135ef3e4b204157f4ea4f81c6f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mongodb@sha256:fd839ab0a7a6434e50dcb32e16f51e0269509936be9f794ec2f4e598d6f8e618
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mongodb@sha256:c0534cf12da8a54419ca88a6d08114ad305cb6674d8d98ea8b0195a7373adfa3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mongodb@sha256:11aac08ce0aac01319d11be907bcfc53ea2354bc236d03fb9d5f4fefae41995f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mongodb@sha256:f9ff0d4dd6f59f05ed17d05adc7df0b9c7584d298d085e22072d095c329be26d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mongodb@sha256:3b970f0eed4560aaad2bcccddf8ec5820d637f96d8ca9992345c59363d3bafdb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mongodb@sha256:550132cfff59bf8e0b4d0e8bce7a45faf281d139c0afd33dcad8dd64dc90ed62
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mongodb@sha256:d2f6f64ecfceb298039e8fe091246528456126bc510e69bed637eea2ab7ca6cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mongodb@sha256:f94e00e3b4cc6bfc1b76708a3b105faee4de158c44ed27dcaa2b6958886b00b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mongodb@sha256:5511eb7e6cf1c1178f7bed78cb89f804ee5d76c751ad39a8e1032b97b64f8974
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mongodb@sha256:79dee8edfb87f55228cba1af1a890e2e64fbb5081fe16ff3cf11564a91c59614